Find out if you have vulnerabilities that put you at risk
Test your applications
Toggle filtering controls
All Vulnerabilities
APPLICATION
Cargo | Rust
Objective-C, CocoaPods | Swift
Composer | PHP
Conan | C/C++
GitHub | Go
Hex | Elixir / Erlang
Maven | Java
npm | JavaScript
NuGet | C#/F#/VB
Pypi | Python
pub | Dart, Flutter
RubyGems | Ruby
Swift Packages | Swift
C/C++
OPERATING SYSTEM
All OS vulnerabilities
AlmaLinux
Alpine Linux
Amazon Linux
CentOS
Chainguard
Debian
MinimOS
Oracle Linux
Red Hat Enterprise Linux
Rocky Linux
SUSE Linux Enterprise Server
Ubuntu
Wolfi
Report a new vulnerability
Vulnerabilities
Packages
M
Incorrect Authorization
Affects
shopware/core
| Versions
<6.6.10.7
>=6.7.0.0, <6.7.3.1
M
Data Amplification
CVE-2025-60790
Affects
processwire/processwire
| Versions
>=0.0.0, <3.0.255
M
Cross-site Scripting (XSS)
CVE-2025-61457
Affects
code16/sharp
| Versions
<9.7.0
M
Server-side Request Forgery (SSRF)
Affects
shopware/platform
| Versions
<6.6.10.7
>=6.7.0.0-dev, <6.7.3.1
M
Server-side Request Forgery (SSRF)
Affects
shopware/core
| Versions
<6.6.10.7
>=6.7.0.0-dev, <6.7.3.1
M
Cross-site Scripting (XSS)
CVE-2025-61417
Affects
tastyigniter/tastyigniter
| Versions
>=0.0.0
H
Incorrect Authorization
CVE-2025-54265
Affects
magento/community-edition
| Versions
<2.4.6-p13
>=2.4.7-beta1, <2.4.7-p8
>=2.4.8-beta1, <2.4.8-p3
>=2.4.9-alpha1, <2.4.9-alpha3
M
Cross-site Scripting (XSS)
CVE-2025-62671
Affects
mediawiki/cargo
| Versions
<3.8.3
H
SQL Injection
CVE-2025-62655
Affects
mediawiki/cargo
| Versions
<3.8.4
M
Incomplete List of Disallowed Inputs
CVE-2025-61924
Affects
prestashop/ps_checkout
| Versions
<5.0.5
>=7.3.1.0, <7.4.4.1
>=8.3.1.0, <8.4.4.1
M
Directory Traversal
CVE-2025-61923
Affects
prestashop/ps_checkout
| Versions
<5.0.5
>=7.3.1.0, <7.4.4.1
>=8.3.1.0, <8.4.4.1
C
Missing Authentication for Critical Function
CVE-2025-61922
Affects
prestashop/ps_checkout
| Versions
<5.0.5
>=7.3.1.0, <7.4.4.1
>=8.3.1.0, <8.4.4.1
M
Cross-site Scripting (XSS)
Affects
ibexa/fieldtype-richtext
| Versions
<4.6.25
>=5.0.0, <5.0.3
M
Cross-site Scripting (XSS)
CVE-2025-62411
Affects
librenms/librenms
| Versions
<25.10.0
M
Cross-site Scripting (XSS)
CVE-2025-62412
Affects
librenms/librenms
| Versions
<25.10.0
M
Information Exposure
Affects
ibexa/user
| Versions
<5.0.3
H
Cross-site Scripting (XSS)
Affects
ibexa/admin-ui
| Versions
>=4.6.0, <4.6.25
>=5.0.0, <5.0.3
H
Cross-site Scripting (XSS)
Affects
ezsystems/ezplatform-admin-ui
| Versions
<2.3.39
H
Improper Validation of Specified Quantity in Input
CVE-2025-56426
Affects
bagisto/bagisto
| Versions
<2.3.7
M
Cross-site Scripting (XSS)
CVE-2025-62365
Affects
librenms/librenms
| Versions
<25.7.0
M
Cross-site Scripting (XSS)
CVE-2025-60880
Affects
bagisto/bagisto
| Versions
<2.3.7
M
Improper Validation of Unsafe Equivalence in Input
CVE-2025-60868
Affects
alt-design/alt-redirect
| Versions
>=1.4.0, <1.6.4
M
Cross-site Scripting (XSS)
CVE-2025-61183
Affects
webreinvent/vaahcms
| Versions
>=0.0.0, <2.3.2
C
Path Equivalence
CVE-2025-10353
Affects
melisplatform/melis-cms-slider
| Versions
<5.3.1
C
SQL Injection
CVE-2025-10351
Affects
melisplatform/melis-cms
| Versions
<5.3.4
C
Missing Authorization
CVE-2025-10352
Affects
melisplatform/melis-core
| Versions
<5.3.11
M
Weak Password Requirements
CVE-2025-11322
Affects
novosga/novosga
| Versions
>=0.0.0
M
Incorrect User Management
CVE-2025-59943
Affects
thorsten/phpmyfaq
| Versions
>=4.0.7, <4.0.13
H
Arbitrary Code Injection
CVE-2025-56588
Affects
dolibarr/dolibarr
| Versions
<21.0.3
M
Directory Traversal
CVE-2025-58769
Affects
auth0/auth0-php
| Versions
>=3.3.0, <8.17.0